Thread: How??
View Single Post
Old 06-07-2008   #3
Google

 
Google's Avatar
 
Last Online: 05-30-2013
Join Date: Jan 2008
Posts: 1,788
Thanks: 10,018
Thanked 1,100 Times in 651 Posts
Groans: 1
Groaned at 6 Times in 6 Posts
Default Re: How??


This is what we see when we try to log to a frozen hotmail account...
The thing is that we cannot stop an idiot from freezing our account...
But It is not a big deal if our account was frozen...
As you see in the picture, all we have to do is to fill the from after we guess the captcha, and our account will be defreezed...
Why hotmail account freezes?
The answer is to prevent an attacker from using a bot to brute force the form (trying a large number of possibilities in a short time...)
When the account is frozen a captcha image is generated...
What is a captcha?
A captcha is a Completely Automated Public Turing test to tell Computers and Humans Apart... so the attacker's bot is unable to read the captcha image because only humans are able to read it... therefore the attacker will no more be able to do a brute force...
As a conclusion, we can freeze a hotmail account without a tool (the tool makes it faster)... and we can also defreeze a hotmail account also without using a tool...
Note that the attacker cannot freeze an account while it is being used at the same time...and he don't have to open a hotmail account while freezing another...

How do we protect our account from being stolen:
-Do not believe in things called write you password to see who blocked you on msn...
-Do not believe in things called send an email to the hotmail sever x supplied by your email and password and the victim email to hack his password...because your email will be hacked not his...
-Do not receive any .com or .exe file when chatting on msn even if you trust the person (because sometimes the file is sent from his/her email without knowing...) so make sure you ask him/her about the file before you accept it... and be careful from mypicture.jpg.com or xxx.bmp.exe ...
-Be careful when you provide your passwords in some sites...
-If you received a message that contains a link, do not click the link when you are in the inbox...just copy it and paste it in another tab... and be carefull from xss and the links with embedded javascript...
-Turn on the internet security settings because some sites can steal your cookies...
-be careful when working in public places... and make sure the PCS aren't running a key logger or spy ware or a Trojan horse...
-make sure your pc is being protect from being hijacked...
-do not give your password to others...

Google is offline   Reply With Quote
The Following 5 Users Say Thank You to Google For This Useful Post:
Kain (06-07-2008), Kingroudy (06-07-2008), Sogelec (06-07-2008), TAREKŪ (06-07-2008), The Queen (06-07-2008)